Files
inquiry_robot/deploy/_remote_mysql_strict_probe.ps1
T

81 lines
3.4 KiB
PowerShell

# Strict MySQL auth probe: never put the success token in the argv that gets echoed on error.
$ErrorActionPreference = "Continue"
$mysql = "C:\yutongda\tools\mysql-8.0.39-winx64\bin\mysql.exe"
$dbCred = Get-Content "C:\yutongda\secure\application-database-credentials.json" -Raw | ConvertFrom-Json
$sec = Get-Content "E:\wwwroot\ops\inquiry_robot_db_secrets.json" -Raw | ConvertFrom-Json
$pgpass = (Get-Content "C:\yutongda\secure\pgpass.txt" -Raw).Trim()
function Test-Login([string]$user, [string]$pass, [string[]]$hostArgs) {
if ([string]::IsNullOrWhiteSpace($user) -or [string]::IsNullOrWhiteSpace($pass)) { return $false }
# Use --batch -N and SELECT 1; success token is only "1" on a line, not present as SQL string in a way... still "SELECT 1" appears in argv.
# Check: no ERROR, and output contains digit 1 as sole result line.
$argList = @()
$argList += $hostArgs
$argList += "-u$user"
$argList += "-p$pass"
$argList += "--connect-timeout=8"
$argList += "--batch"
$argList += "-N"
$argList += "-e"
$argList += "SELECT 1"
$out = & $mysql @argList 2>&1
$text = ($out | ForEach-Object { "$_" }) -join "`n"
if ($text -match "ERROR\s+\d+") { return $false }
$lines = $out | ForEach-Object { "$_".Trim() } | Where-Object { $_ -ne "" -and $_ -notmatch "Warning" }
return ($lines -contains "1")
}
Write-Output "=== users/hosts matrix (bool only) ==="
$users = @(
@{ u = "root"; p = [string]$dbCred.mysql_password; src = "app.mysql_password" },
@{ u = "root"; p = [string]$dbCred.postgres_password; src = "app.postgres_password" },
@{ u = "root"; p = $pgpass; src = "pgpass" },
@{ u = [string]$dbCred.mysql_username; p = [string]$dbCred.mysql_password; src = "app.mysql_user" },
@{ u = "inquiry_robot"; p = [string]$sec.mysql_password; src = "secrets.ir" }
)
$hostModes = @(
@{ n = "socket"; a = @() },
@{ n = "127"; a = @("-h127.0.0.1","-P3306") },
@{ n = "remote"; a = @("-h10.206.0.14","-P3306") }
)
foreach ($u in $users) {
foreach ($h in $hostModes) {
$ok = Test-Login $u.u $u.p $h.a
Write-Output ("ok=" + $ok + " user=" + $u.u + " src=" + $u.src + " mode=" + $h.n + " passLen=" + $u.p.Length)
}
}
Write-Output "=== search initialize / temporary password logs ==="
$logDirs = @(
"C:\yutongda\tools\mysql-8.0.39-winx64",
"C:\yutongda\data\mysql",
"C:\yutongda\logs",
"C:\yutongda\ops\logs",
"C:\ProgramData\MySQL"
)
foreach ($d in $logDirs) {
if (-not (Test-Path $d)) { continue }
Get-ChildItem $d -Recurse -Include *.err,*.log,*.txt -EA SilentlyContinue -Depth 2 |
Select-String -Pattern "temporary password|A temporary password|root@localhost" -EA SilentlyContinue |
Select-Object -First 5 |
ForEach-Object {
$t = $_.Line
if ($t -match 'password') { "FILE=$($_.Filename) REDACTED_line" } else { "FILE=$($_.Filename) $($t.Substring(0,[Math]::Min(100,$t.Length)))" }
}
}
Write-Output "=== services / mysqld cmdline ==="
Get-CimInstance Win32_Process -Filter "Name='mysqld.exe'" -EA SilentlyContinue |
ForEach-Object { "pid=$($_.ProcessId) cmd_len=$($_.CommandLine.Length)" }
Get-Service *mysql* -EA SilentlyContinue | Format-Table Name,Status,StartType -AutoSize | Out-String | Write-Output
Write-Output "=== admin-login-recovery / secure listing ==="
cmd /c "dir /b C:\yutongda\secure 2>nul"
cmd /c "dir /s /b C:\yutongda\secure\*mysql* 2>nul"
cmd /c "dir /s /b C:\yutongda\secure\*root* 2>nul"
cmd /c "dir /s /b C:\yutongda\secure\admin* 2>nul"
Write-Output "DONE"